Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-0105

Опубликовано: 15 апр. 2014
Источник: debian
EPSS Низкий

Описание

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-keystoneclientfixed1:0.6.0-4package
python-keystoneclientnot-affectedwheezypackage
keystonefixed2013.1.1-2package
keystoneno-dsawheezypackage

Примечания

  • From 2013.1.1-2 the auth_token.py is in python-keystoneclient

EPSS

Процентиль: 59%
0.00371
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

redhat
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

nvd
почти 12 лет назад

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

CVSS3: 6
github
больше 3 лет назад

python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware

EPSS

Процентиль: 59%
0.00371
Низкий